[sleuthkit-users] Using Autopsy and the Sleuthkit
Brought to you by:
carrier
From: Horner, J. J (JH8) <ho...@y1...> - 2004-01-16 14:53:13
|
Where can I find a good intro to using these packages? I've got them installed, installed the NSRL hash sets, and I've got an image loaded to examine. I can generally find most things, but I am unsure how to exclude from my file listings any file that appears to be normal (a.k.a. matches the hash for a known good OS file). Any Autopsy HOWTOs anywhere? Thanks, J. J. Horner (Jon) CISSP,CCNA,C3E,CHSS,CHP NCI Information Systems, Inc. office: 865-576-0585 cell : 865-680-1369 "Individualists Unite! Dyslexics Untie!" |